Virus Database


Macro.Word97.Lopez

Description Macro.Word97.Lopez

The virus replicates under MS Word ver. 8.0 only. It contains two modules Word97Virus1 and NewMacros. The "Word97Virus1" module contains eleven macros: Word97Virus1, AutoNew, AutoClose, AutoExec, AutoSave, AutoOpen, FileClose, FileNew, FileSaveAs, FilePrint, FileOpen. The virus replicates when any of these macros is activated.
The "NewMacros" module contains one macro ToolsMacro that on entering the Tools/Macro menu deletes virus macros in active document and NORMAL.DOT.
On printing the virus appends to the document the text:
hE wHo LiVeS iN tHe PaSt HaS nO ChAnCe To SuRviVe In ThE fUtUrEall

The virus also contains the comment:
Word97Virus1 Macro

Check other viruses! Be aware! Use Antiviral Software

Sister.902

Description Sister.902

It is not a dangerous nonmemory resident encrypted parasitic virus. It searches for EXE files, then writes itself to the end of the file. To locate EXE files the virus scans current and parent directories, then WINDOWSCOMMAND directory, looks for *.EXE and *.OVL files there and infects them. The virus also looks for the EDIT.COM file - it is not "true" COM file, but has EXE binary format starting from DOS 7 (Windows95). The virus checks file names and does not infect files: F-*, AV*, DR*, SC*, IV*, TB*, FI*, FV* (F-PROT, AVP, DRWEB, SCAN, etc).
The virus deletes the anti-virus data files: ANTI-VIR.DAT, IVB.NTZ. It also tries to delete CHKLIST.* data files, but fails because of a bug.
Depending on the system timer the virus manifests itself with a video effect and display the text:
Sisters
3 close friends

The virus also contains the text strings:
[Sisters]
Techno Phunk/Ti

Sisters.2221

Description Sisters.2221

It is a very dangerous memory resident encrypted parasitic virus. It hooks INT 21h, 16h and writes itself to the end of COM and EXE files that are executed.
The virus deletes the anti-virus data files: CHKLIST.MS and CHKLIST.CPS.
Depending on its internal counter and current date the virus: disables the mouse driver, erases 40 sectors on the C: drive, erases the CMOS memory, halts the computer, displays the messages:
TEMPLE OF LOVE V1.0 MS 95
FoUnD VIRUS SYSTERS OF MERCY iN yOuR sYsTeM !!!

The virus INT 16h handler (keyboard) erases the CMOS memory after 700th keys entered.
The virus also contains the strings:
SyStEm is now halted.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Massive
Athletikum Group
Sklep Sportowy
Datoraktuellt

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com